Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86321

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 5.3

Описание

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

A flaw was found in jackson-coreutils. This server-side request forgery (SSRF) vulnerability occurs when applications use the JsonLoader.fromURL function with untrusted input. A remote attacker can exploit this to induce the server to make arbitrary requests. This could lead to unauthorized information disclosure or access to internal network resources.

Отчет

Moderate: A server-side request forgery (SSRF) vulnerability exists in jackson-coreutils when applications use JsonLoader.fromURL with untrusted input. This flaw allows a remote attacker to induce the server to make arbitrary requests, potentially leading to information disclosure or access to internal network resources. The impact is considered Moderate due to the need for an application to expose this functionality to untrusted input.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7jackson-coreutilsOut of support scope
Red Hat JBoss Enterprise Application Platform 7jackson-coreutilsOut of support scope
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk11-openshift-rhel8Out of support scope
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk17-openshift-rhel8Out of support scope
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk8-openshift-rhel8Out of support scope
Red Hat JBoss Enterprise Application Platform 8jackson-coreutilsFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packjackson-coreutilsFix deferred
Red Hat Single Sign-On 7jackson-coreutilsOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2529509com.github.fge/jackson-coreutils: java-json-tools jackson-coreutils: Server-Side Request Forgery via JsonLoader.fromURL

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
9 дней назад

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 5.3
github
8 дней назад

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

5.3 Medium

CVSS3